DNS cannot resolve internet addresses

Posted on 2004-10-28
Last Modified: 2010-04-10
We have two Windows Server 2003 DCs running DNS that have been allowing name resolution of internet sites just fine for a few weeks.   I'll call them "DNS-1" and "DNS-2" for reference.  DNS-1 is the primary DNS server and the first DC we brought online.  Suddenly, yesterday the DNS servers quit resolving names of internet sites.  

If it helps we are currently running both this 2003 test AD domain and a production NT 4 domain (each domain trusts the other).  There are separate DNS servers on each domain.  As stated, a couple weeks ago when we set this up all name resolutions worked fine from either domain when using the DNS.  The same name records exist on the DNS servers in both domains.

There are not any blatant DNS errors in the Event logs for DNS or AD.  You can ping outside IP addresses just fine from either AD DNS servers, but it will not resolve names.  I've run NETDIAG and DCDIAG, and AD and DNS both come back with "pass" on the tests.  

I can't point to any recent changes in our network, so that doesn't seem to be the case, but because I see no errors on DNS-1 or DNS-2.

I've verified the DNS settings on the servers per Microsofts "best practices for DNS", and this thing worked great with no real explanation as to the sudden problems.....

I'm no DNS expert, so any advice on additional troubleshooting tools, etc.
Question by:Darthyw
    LVL 38

    Accepted Solution


       In you DNS-1, please check the DNS (Start-> Programs->Administrative Tools-> DNS)
    and right click on "DNS-1" (hostname) ->Properties --> check the Forwarders tag

       There should be 1 or 2 IP addresses. First, do you enable forwarder?
    Second, write down the IP addresses.
    And ping the IP addresses first.
    If ping ok, then do
    c:\> nslookup
    > server <IP you write down>

    The result?

       You can check other tag to see anything suspious.

    Good luck,

    LVL 2

    Expert Comment


    This could mean that you have a TCP/IP stack corruption since you say that there was no changes done and it suddenly stopped working.

    You could try to to remove the network card drivers and TCP/IP and re-install those.

    Before that check the config on the DNS server if you have a backup on the day that worked to compare and see what changed.

    Also make sure their was no other changes done on that machine that could have caused this.
    I would also run a spyware and virus check to make sure nothing like that has caused this.
    LVL 1

    Expert Comment

    I once had a 2k Server with an infection called w32 hostblock, that made the host file in C:\WINNT\system32\drivers\etc Folder slightly corrupt. Mainly the line

    local host    

    As Dns lookups try this file before DNSMGMT.exe does it's thing, even with 2k Server. It can prevent name resolution from taking place properly. As it did in this one off instance for me.
    As wesly_chen above said if you are using forwarders you mut be able to ping them, although I am sure you have probably done that.

    Good Luck

    Author Comment

    Thanks for the prompt information, but forwarding seems to have been the issue, which another engineer here was suspecting.  However, we don't have forwarding set up in DNS on the NT 4.0 domain, so it was throwing us a loop.  I don't know how it's been working for a week.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone. Privacy Policy Terms of Use

    Featured Post

    6 Surprising Benefits of Threat Intelligence

    All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

    I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
    If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
    Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    877 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now